CloudFiles supports two authentication methods for SharePoint - Integration User and Service Principal. Only one method is active for automations at any given time.
| Method | What it uses | Best for |
|---|---|---|
| Integration User | A real Microsoft user account in your tenant | Fastest way to get started. Works well for teams that already have a dedicated integration account and are comfortable managing MFA, license, and password policies on it. |
| Service Principal | The CloudFiles app registered in your Microsoft tenant, approved once by a Global Administrator | Long-running, reliable connections. No user account, no license consumed, no risk of the connection breaking due to MFA prompts, password rotation, or user offboarding. |
See also: for a conceptual deep-dive on choosing between the two authentication methods, see SharePoint Connection Methods: Integration User vs Service Principal.
Integration User
The Integration User allows you to connect an account-level SharePoint account, which is used for automations like file backup and organization. To configure, follow the steps below -
- Navigate to the "Libraries" page and access the SharePoint section on the canvas.
- Under "Integration User," click the Connect button.
- Log in to the Microsoft account associated with SharePoint, or select the account if already logged in.
- Once connected, the username and connection date will be displayed under "Integration User."
- To change the Integration User, use the Disconnect option and repeat the process.

Service Principal
With service principal, CloudFiles authenticates as the CloudFiles app already registered in your Microsoft tenant. A Global Administrator approves app-level permissions once, and the connection then runs without a user account, license, MFA prompt, or password rotation risk.
The setup happens in three parts: the Salesforce admin generates a setup link, a Microsoft Global Administrator approves the permissions using that link, and the Salesforce admin then activates service principal for automations.
- Under Service principal, click Setup. The status shows Not configured until this step is completed.
- In the Tenant URL field, enter your SharePoint tenant URL (for example, https://cloudfileswork.sharepoint.com).
- Click Generate. CloudFiles generates a setup link and the status changes to Awaiting admin consent. The setup link is active for 7 days.
- Copy the setup link and share it with your Microsoft Global Administrator. This admin is often not a Salesforce user, which is why the link is shareable and does not require a CloudFiles or Salesforce login.
- Ask the admin to open the link and approve the permissions requested for the CloudFiles app. Once approved, the status on the SharePoint tab changes to Consent granted.
- Return to the SharePoint tab and click Switch automations to service principal.
Conflict Behaviors
Specify how the system should handle duplicate files or folders during operations in SharePoint:
- File Conflict Behavior: Options include Rename, Replace, No Op, or Fail.
- Folder Conflict Behavior: Options include No Op, Rename, or Fail.
Register Sites
This option is only needed if you wish to restrict which sites are displayed and available for use. Only registered SharePoint sites will be accessible for users connecting their SharePoint account with CloudFiles. To register a site:
- Click the Register button under the "Register Sites" section.
- In the popup window, paste the URL of the SharePoint site (e.g., https://cloudfileswork.sharepoint.com/sites/Demo1) and click Register.
- The registered sites will appear as a list in the same section.
- To remove a site, click the delete icon next to it and confirm the action in the "Remove Site" popup.

SharePoint features you can control from Salesforce
As well as storing files, CloudFiles can set up and manage SharePoint itself from Salesforce Flow or Apex. A new customer, deal or project can get its own SharePoint site, libraries and metadata without anyone opening SharePoint.
Create workspaces automatically
- Create SharePoint sites. Create a site when a record is created or reaches a stage, for example one site per customer or project. Choose the site template, apply a site design so every site starts with the same layout and structure, and add the site admins in the same step.
- Create document libraries. Add a library to any site with the site columns and content types it needs already attached. You can also stop the library inheriting the site's permissions, so its access can be set separately.
- Create Microsoft Teams. Create a team from a Teams template, or copy an existing team along with its channels, tabs, apps, settings and members.
Manage SharePoint metadata from Salesforce
- Set column values. Write Salesforce data into SharePoint columns on files and folders. Supported column types are single line of text, multiple lines of text, number, yes/no, date and time, and choice. Users can also edit these values in the CloudFiles widget.
- Set column defaults. Set a library column's default value and display name, and show the column in the library's default view, so new files are tagged as soon as they are added.
- Search files and folders. Search by file or folder name, including part of a name, or by the value of a SharePoint column, for example every document where Status is Approved. The CloudFiles widgets have a simple search bar, and in a flow you can also combine several conditions with AND or OR.
Respond to changes made in SharePoint
- Capture SharePoint events. Start a Salesforce flow when a file is uploaded to SharePoint or its properties change, including changes made directly in SharePoint rather than through CloudFiles. This needs a premium Power Automate licence.
Control access
- Manage access with site groups. Create SharePoint site groups and add or remove their members, so access to a site follows group membership.
- Grant or remove access by email. Give a person access to a file or folder, or take it away, using their email address.
Work across multiple sites and libraries
- Use as many sites and libraries as you need. Connect any number of SharePoint sites and libraries in your Microsoft tenant, and point each widget or flow at the one it should use.
SharePoint Rest API Authorization
This authorization is necessary for advanced functionalities such as site creation and property searches within flows. To connect:
- In the Tenant URL box, paste the URL of the SharePoint (e.g., https://cloudfileswork.sharepoint.com) and click Connect.
- Log in to the Microsoft account associated with SharePoint, or select the account if already logged in.
- Accept the Permissions requested by clicking "Accept"
- The authorized Tenant URL along with the username and connection date will be displayed under the same section.
- To deauthorize, simply click the Disconnect button.
